UBUNTU-CVE-2023-40547

Source
https://ubuntu.com/security/CVE-2023-40547
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-40547.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2023-40547
Related
Published
2024-01-23T00:00:00Z
Modified
2024-11-06T16:33:16Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.

References

Affected packages

Ubuntu:Pro:14.04:LTS / shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.4-0ubuntu4
0.8-0ubuntu2
0.9+1474479173.6c180c6-1ubuntu1

Other

13-0ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:14.04:LTS / shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3
1.4
1.5
1.6
1.9
1.17~14.04.1
1.18~14.04.1
1.19~14.04.1
1.32~14.04.2
1.33.1~14.04.2
1.33.1~14.04.3
1.33.1~14.04.4
1.33.1~14.04.5

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.8-0ubuntu2
0.9+1474479173.6c180c6-1ubuntu1

Other

13-0ubuntu2

15+1533136590.*

15+1533136590.3beb971-0ubuntu1

15+1552672080.*

15+1552672080.a4a1fbe-0ubuntu2

15.*

15.4-0ubuntu7

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.11
1.12
1.17~16.04.1
1.18~16.04.1
1.19~16.04.1
1.27~16.04.1
1.28~16.04.1
1.32~16.04.1
1.33.1~16.04.1
1.33.1~16.04.2
1.33.1~16.04.3
1.33.1~16.04.4
1.33.1~16.04.5
1.33.1~16.04.6
1.33.1~16.04.10

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim?arch=src?distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.9+1474479173.6c180c6-1ubuntu1

Other

13-0ubuntu2

15+1533136590.*

15+1533136590.3beb971-0ubuntu1

15+1552672080.*

15+1552672080.a4a1fbe-0ubuntu2

15.*

15.4-0ubuntu7
15.4-0ubuntu9
15.7-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed?arch=src?distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.32
1.33.1
1.34.4
1.34.5
1.34.6
1.34.7
1.34.8
1.34.9
1.34.9.1
1.34.9.2
1.37~18.04.1
1.37~18.04.2
1.37~18.04.3
1.37~18.04.6
1.37~18.04.8
1.37~18.04.10
1.37~18.04.11
1.37~18.04.13

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

15+1533136590.*

15+1533136590.3beb971-0ubuntu1

15+1552672080.*

15+1552672080.a4a1fbe-0ubuntu1
15+1552672080.a4a1fbe-0ubuntu2

15.*

15.4-0ubuntu7
15.4-0ubuntu9
15.7-0ubuntu1
15.8-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.39
1.40
1.40.3
1.40.4
1.40.6
1.40.7
1.40.9
1.40.10
1.41

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

15.*

15.4-0ubuntu9
15.7-0ubuntu1
15.8-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.51
1.51.3
1.51.4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.8-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "15.8-0ubuntu1",
            "binary_name": "shim"
        },
        {
            "binary_version": "15.8-0ubuntu1",
            "binary_name": "shim-dbg"
        }
    ]
}

Ubuntu:24.10 / shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.58+15.8-0ubuntu1",
            "binary_name": "shim-signed"
        }
    ]
}

Ubuntu:24.04:LTS / shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.8-0ubuntu1

Affected versions

15.*

15.7-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "15.8-0ubuntu1",
            "binary_name": "shim"
        },
        {
            "binary_version": "15.8-0ubuntu1",
            "binary_name": "shim-dbg"
        }
    ]
}

Ubuntu:24.04:LTS / shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.58

Affected versions

1.*

1.56
1.57

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.58+15.8-0ubuntu1",
            "binary_name": "shim-signed"
        }
    ]
}